PT-2025-11257 · Purethemes · The Realteo - Real Estate Plugin
Tonn
·
Published
2025-03-14
·
Updated
2025-03-14
·
CVE-2025-2232
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
The Realteo - Real Estate Plugin by Purethemes versions 1.2.8 and earlier
Description:
The issue is due to insufficient role restrictions in the
do register user function, making it possible for unauthenticated attackers to register an account with the Administrator role. This allows attackers to bypass authentication.Recommendations:
For versions 1.2.8 and earlier, update to a version later than 1.2.8 to resolve the issue.
As a temporary workaround, consider disabling the
do register user function until a patch is available.Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Realteo - Real Estate Plugin